Committed provider fixtures and routing expectations on golden corpus repos
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 45/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- go
- Área
- cli, testing-qa, tooling
Línea de trabajo
Start with tests/tools/README.md and the existing fixtures under tests/tools/fixtures/, then inspect tests/map_corpus/golden_expectations.json and the provider ingesters in pkg/providerjoin/. Add pinned or inventory/fence-based fixtures and routing expectations for the seven named repositories, covering the listed tools and blind-spot reasons. Done means the golden-corpus attribution, prerequisite, routing, and SARIF expectations are validated without relying on Bifrost in the offline container.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Committed provider fixtures and routing expectations on golden corpus repos
Background
Issues #77, #78, #79 and #82 each require validation against real, pinned tool runs on the 7 golden corpus repositories (loki, mastodon, ruff, spring-petclinic, superset, terraform-aws-vpc, aws-sam-java-rest). On main, all four issues have been tested only on synthetic 3–5 file applications (flask-app, express-app, spring-app) in tests/tools/fixtures/. The golden corpus repos have no provider fixtures.
What 1.0 ships
- All four provider ingesters work on synthetic fixtures:
pkg/providerjoin/syft.go,sarif.go,noir.go,bifrost.go. dircue map --attach KIND=PATHsupportssyft-json,sarif,noir-json,bifrost-code-query-json.dircue map routeemits inert per-component routing plans.- The coverage ledger reports blind spots with correct reasons on synthetic inputs.
- Three SARIF emitter kinds (Noir, ruff, Semgrep) are tested on synthetic apps.
Remaining work (acceptance criteria from original issues)
From #77: Committed, pinned Syft fixtures on every golden corpus repo; Noir fixtures on the web-framework entries (mastodon, superset, loki); Bifrost on a subset. Attribution precision/recall measured against hand-written expectations on golden corpus entries.
From #78: On golden corpus entries with pinned tool runs, the expected blind spots are reported with the correct reasons: unsupported language, unmet build prerequisite, missing run, crashed run.
From #79: On the golden corpus, applicable tools and unmet prerequisites match hand-written expectations. Routing expectation fields added to tests/map_corpus/golden_expectations.json.
From #82: SARIF locate fixtures from at least three emitters of different kinds on golden corpus entries (not just synthetic apps).
Constraints: Bifrost is not runnable in the hermetic offline container environment. Syft on each of 7 golden repos will produce large fixtures — use the inventory/fence pattern from #88 rather than committing raw output.
Links
- #77, #78, #79, #82 (1.0.0 issues being closed)
tests/tools/README.md(existing tools oracle)tests/map_corpus/golden_expectations.json
- Lenguaje dominante
- Go
- Estrellas
- 0
- Forks
- 0
- Merge medio
- 5 h 8 min
- PR fusionados (30 d)
- 54
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de war-and-code/dircue
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
war-and-code/dircue#200 ·
Los mantenedores suelen responder en 1 día
-
follow-up
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
war-and-code/dircue#179 ·
Los mantenedores suelen responder en 1 día
-
follow-up
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
war-and-code/dircue#178 ·
Los mantenedores suelen responder en 1 día
-
enhancement follow-up
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
war-and-code/dircue#172 ·
Los mantenedores suelen responder en 1 día
-
enhancement follow-up
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
war-and-code/dircue#171 ·
Los mantenedores suelen responder en 1 día
Todos los issues de war-and-code/dircue
Issues similares
-
raised-by:worker
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
medici-finance/assay#2486 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
openimsdk/openim-sdk-core#1127 ·
-
github_actions
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
Hochfrequenz/aibap.mcp#578 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
mvanhorn/cli-printing-press#4980 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
lenaxia/LLMSafeSpaces#1644 · 3 comentarios · 1 reacción ·
Los mantenedores suelen responder en 1 día